ProCurve 6200yl User's Guide Page 307

  • Download
  • Add to my manuals
  • Print
  • Page
    / 596
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 306
10-21
Access Control Lists (ACLs)
Overview
One inbound and one outbound RACL filtering routed IP traffic
moving through the port for VLAN “X”. (Also applies to inbound,
switched traffic on VLAN “X” that has a destination on the switch
itself.”
Note In cases where an RACL and any type of port or VLAN ACL are filtering traffic
entering the switch, the switched traffic explicitly permitted by the port or
VLAN ACL is not filtered by the RACL (except when the traffic has a destina-
tion on the switch itself). However, routed traffic explicitly permitted by the
port or VLAN ACL (and any switched traffic having a destination on the switch
itself) must also be explicitly permitted by the RACL, or it will be dropped.
Also, a switched packet is not affected by an outbound RACL assigned to the
VLAN on which the packet exits from the switch.
A Packet Must Have a Match with a “Permit” ACE in All Applicable
ACLs Assigned to an Interface. On a given interface where multiple ACLs
apply to the same traffic, a packet having a match with a deny ACE in any
applicable ACL on the interface (including an implicit deny any) will be
dropped.
For example, suppose the following is true:
Port A10 belongs to VLAN 100.
A static port ACL is configured on port A10.
A VACL is configured on VLAN 100.
An RACL is also configured for inbound, routed traffic on VLAN 100.
An inbound, switched packet entering on port A10, with a destination on port
A12, will be screened by the static port ACL and the VACL, regardless of a
match with any permit or deny action. A match with a deny action (including
an implicit deny) in either ACL will cause the switch to drop the packet. (If
the packet has a match with explicit deny ACEs in multiple ACLs and the log
option is included in these ACEs, then a separate log event will occur for each
match.) The switched packet will not be screened by the RACL.
However, suppose that VLAN 2 in figure 10-4 (page 10-22) is configured with
the following:
A VACL permitting IP traffic having a destination on the 10.28.10.0
subnet
Page view 306
1 2 ... 302 303 304 305 306 307 308 309 310 311 312 ... 595 596

Comments to this Manuals

No comments